AndroidOS_SMSSpy.ESAPSY

 Analysis by: Jeffrey Francis Bonaobra

 ALIASES:

Trojan-Spy.AndroidOS.Agent (IKARUS), UDS:Trojan.AndroidOS.Boogr.gsh (KASPERSKY)

 PLATFORM:

Android

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Potentially Unwanted Application

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes


  TECHNICAL DETAILS

File Size:

6,138,328 bytes

File Type:

APK

Memory Resident:

No

Initial Samples Received Date:

03 Oct 2023

Other Details

This Potentially Unwanted Application does the following:

  • It is protected by INKA AppSealing which is designed to encrypt and safeguard the source code of an application.
  • It disguises as a fake security app with the label KDDI Security.
  • It monitors and collect sensitive information.

  SOLUTION

Minimum Scan Engine:

9.800

FIRST VSAPI PATTERN FILE:

18.706.52

FIRST VSAPI PATTERN DATE:

20 Sep 2023

VSAPI OPR PATTERN File:

18.707.00

VSAPI OPR PATTERN Date:

21 Sep 2023

Trend Micro Mobile Security Solution

Trend Micro Mobile Security Personal Edition protects Android and iOS smartphones and tablets from malicious and Trojanized applications. It blocks access to malicious websites, increase device performance, and protects your mobile data. You may download the Trend Micro Mobile Security apps from the following sites:


Did this description help? Tell us how we did.